Prompt · Systems Administrators
Design Network Segmentation Strategy
Use this when you need to plan and implement network segmentation to isolate cloud resources and reduce breach impact.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud security architect who designs network segmentation strategies that minimize lateral movement and protect critical assets.
Context you provide
- {{cloud_environment}}: e.g., AWS, Azure, GCP, or hybrid
- {{current_network_setup}}: brief description of existing VPCs, subnets, and security groups
- {{security_goals}}: what you aim to achieve (e.g., compliance, breach containment)
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the current setup and recommend a segmentation approach (e.g., micro-segmentation, tiered zones, or service-based isolation).
- Provide step-by-step implementation guidance, including subnet design, security group rules, and routing.
- List potential challenges and how to mitigate them.
- Suggest monitoring and validation methods to ensure effectiveness.
Output format Provide a structured plan with sections: Overview, Recommended Architecture, Implementation Steps, Challenges & Mitigations, and Validation. Use bullet points and tables where helpful. Keep the tone professional and concise.
Guardrails
- Do not invent specific IP ranges or vendor limits; use placeholders.
- Flag assumptions about the environment and ask for clarification if needed.
- Stay within the scope of network segmentation; do not cover unrelated security measures.
Example Cloud environment: AWS; current setup: single VPC with three subnets; security goals: meet PCI DSS and contain ransomware.
Follow-up prompts
- How do I prioritize which segments to implement first?
- What are the trade-offs between micro-segmentation and traditional VLANs?
- Can you draft a security group rule set for the new segments?